CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-46673 HIGH
Russh < 0.60.3 CryptoVec - Unbounded Allocation Resource Exhaustion
CVSS 7.5
CVE-2026-45664 MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-45031 MEDIUM
ImageMagick: Policy Bypass in PSD decoder
CVSS 5.3
CVE-2026-10740 MEDIUM
Excessive memory allocation in s2n-quic
CVSS 5.3
CVE-2026-24720 MEDIUM
QNAP File Station 5 < 5.5.6.5243 - Resource Exhaustion
CVSS 6.5
CVE-2026-41726 MEDIUM
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVSS 6.5
CVE-2026-41716 HIGH
Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names
CVSS 7.5
CVE-2026-28237 MEDIUM
Amd µProf - Allocation of Resources Without Limits or Throttling
CVSS 5.5
CVE-2026-49955 MEDIUM
Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVSS 5.3
CVE-2026-45591 HIGH
Microsoft ASP.NET Core - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-42570 HIGH
Svelte devalue: DoS via sparse array deserialization
CVSS 7.5
CVE-2026-41851 MEDIUM
Spring Framework Denial of Service via Unbounded Cache in SpEL
CVSS 5.3
CVE-2026-41710 MEDIUM
Cache Exhaustion in Stateful Retries leads to Denial of Service
CVSS 5.9
CVE-2026-41007 HIGH
Spring HATEOAS heap exhaustion through unbounded internal caching
CVSS 7.5
CVE-2026-40984 HIGH
Micrometer HTTP server instrumentations DoS vulnerability
CVSS 7.5
CVE-2026-40983 HIGH
Micrometer gRPC server instrumentation DoS vulnerability
CVSS 7.5
CVE-2026-43973 HIGH
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
CVE-2026-45290 HIGH
Cloudburst Network has DoS in RakNet connection handling due to missing bound checks
CVSS 7.5
CVE-2026-50589 MEDIUM
Openstack Ironic < 35.0.1 - Allocation of Resources Without Limits or Throttling
CVSS 5.3
CVE-2026-40898 MEDIUM
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVSS 5.3
CVE-2026-36499 MEDIUM
Open vSwitch v3.6.90 - Denial of Service via Excessive Thread Allocation in udpif_set_threads()
CVSS 6.5
CVE-2026-44545 MEDIUM
Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service
CVSS 5.3
CVE-2026-48597 HIGH
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
CVE-2026-35202 LOW
Pterodactyl Panel <1.12.3 Client API - Database Limit Bypass
CVE-2026-34077 HIGH
React Router vulnerable to Denial of Service via reflected user input in single-fetch
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High